VYPR

CVEs

115,889 total · page 776 of 2,318

  • CVE-2025-1596HigFeb 23, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely.…

  • CVE-2022-28339HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

  • CVE-2025-27012HigFeb 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.This issue affects A1POST.BG Shipping for Woo: from n/a through <= 1.5.

  • CVE-2025-26774HigFeb 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups easy-popups allows Reflected XSS.This issue affects Responsive Modal Builder for High Conversion – Easy…

  • CVE-2025-26760HigFeb 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Builder calculator-builder allows PHP Local File Inclusion.This issue affects Calculator Builder: from n/a through <= 1.6.2.

  • CVE-2025-26757HigFeb 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer full-customer allows PHP Local File Inclusion.This issue affects FULL Customer: from n/a through <= 3.1.26.

  • CVE-2025-26756HigFeb 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips magic-the-gathering-card-tooltips allows Stored XSS.This issue affects Magic the Gathering Card Tooltips: from n/a through <= 3.5.0.

  • CVE-2024-52939HigFeb 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.

  • CVE-2024-46975HigFeb 22, 2025
    risk 0.51cvss 7.9epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.

  • CVE-2024-12577HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2025-0957HigFeb 22, 2025
    risk 0.40cvss 7.2epss 0.00

    The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

  • CVE-2025-0953HigFeb 22, 2025
    risk 0.40cvss 7.2epss 0.00

    The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

  • CVE-2025-0918HigFeb 22, 2025
    risk 0.40cvss 7.2epss 0.00

    The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

  • CVE-2024-13869HigFeb 22, 2025
    risk 0.40cvss 7.2epss 0.02

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated…

  • CVE-2025-21704HigFeb 22, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and discard the notification…

  • CVE-2025-1361HigFeb 22, 2025
    risk 0.42cvss 7.5epss 0.01

    The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the…

  • CVE-2024-13474HigFeb 22, 2025
    risk 0.49cvss 7.5epss 0.00

    The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2025-1510HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2025-1509HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…

  • CVE-2024-13899HigFeb 22, 2025
    risk 0.47cvss 7.2epss 0.01

    The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with…

  • CVE-2025-27109HigFeb 21, 2025
    risk 0.40cvss 7.3epss 0.00

    solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX…

  • CVE-2025-27108HigFeb 21, 2025
    risk 0.40cvss 7.3epss 0.00

    dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginning with `$`. Particularly, when the…

  • CVE-2025-27106HigFeb 21, 2025
    risk 0.50cvss 8.8epss 0.02

    binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of…

  • CVE-2025-27104HigFeb 21, 2025
    risk 0.42cvss 7.5epss 0.00

    vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects produced in the loop body (e.g. read a…

  • CVE-2025-26622HigFeb 21, 2025
    risk 0.42cvss 7.5epss 0.00

    vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of decimals. Unfortunately, improper handling of the oscillating final states may lead to sqrt incorrectly returning rounded up results. This…

  • CVE-2025-25282HigFeb 21, 2025
    risk 0.53cvss 8.1epss 0.00

    RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts,…

  • CVE-2025-1555HigFeb 21, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-25769HigFeb 21, 2025
    risk 0.52cvss 8.0epss 0.00

    Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.

  • CVE-2025-25876HigFeb 21, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data.

  • CVE-2024-57176HigFeb 21, 2025
    risk 0.49cvss 7.6epss 0.01

    An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL.

  • CVE-2025-1546HigFeb 21, 2025
    risk 0.48cvss 7.3epss 0.03

    A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code…

  • CVE-2025-1403HigFeb 21, 2025
    risk 0.49cvss 8.6epss 0.01

    Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

  • CVE-2025-26013HigFeb 21, 2025
    risk 0.53cvss 8.2epss 0.00

    An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

  • CVE-2025-1539HigFeb 21, 2025
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. Affected by this issue is the function replace_special_char of the file /storagein.pd-XXXXXX. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely.…

  • CVE-2025-1538HigFeb 21, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed…

  • CVE-2025-1536HigFeb 21, 2025
    risk 0.48cvss 7.3epss 0.03

    A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument…

  • CVE-2025-26794HigFeb 21, 2025
    risk 0.06cvss 7.5epss 0.77

    Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

  • CVE-2025-1535HigFeb 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to…

  • CVE-2024-9150HigFeb 21, 2025
    risk 0.57cvss epss 0.00

    Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and…

  • CVE-2025-1471HigFeb 21, 2025
    risk 0.00cvss 7.8epss 0.00

    In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion…

  • CVE-2024-13353HigFeb 21, 2025
    risk 0.50cvss 8.8epss 0.01

    The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via several widgets. This makes it possible for authenticated attackers, with…

  • CVE-2025-0728HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size.…

  • CVE-2025-0727HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data…

  • CVE-2025-0726HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further…

  • CVE-2024-11260HigFeb 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2025-27088HigFeb 20, 2025
    risk 0.46cvss 8.2epss 0.00

    oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing…

  • CVE-2025-25679HigFeb 20, 2025
    risk 0.52cvss 8.0epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

  • CVE-2025-22973HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.

  • CVE-2025-27097HigFeb 20, 2025
    risk 0.42cvss 7.5epss 0.00

    GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single…

  • CVE-2025-0352HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.